# Envira Gallery <= 1.16.1 - Authenticated (Contributor+) Insecure Direct Object Reference to Private Post Title and Excerpt Disclosure via gallery_data REST Field

- **ID:** WPSEC-2026-0682
- **Plugin:** Envira Gallery – Image Photo Gallery, Albums, Video Gallery, Slideshows & More (`envira-gallery-lite`), https://wordpress.org/plugins/envira-gallery-lite/
- **Affected versions:** all versions before 1.16.2
- **Fixed in:** 1.16.2 (Update to 1.16.2 or later.)
- **Severity:** Medium 4.3 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N)
- **Weakness:** CWE-639
- **Usage among sites WPSec scans:** plugin Low, affected versions Low (as of 2026-10-08)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/envira-gallery-lite
- **Fix released:** 2026-10-07
- **Published:** 2026-10-08
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0682/

## Description

The Envira Gallery plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.16.1. The update callback of the gallery_data REST field accepted any post ID as a gallery image without checking that the user was allowed to use it, and stored that post's title and excerpt in the gallery, from where they are returned in the REST response. This makes it possible for authenticated attackers with gallery access, which contributors have by default, to read the titles and excerpts of private, draft and password-protected posts they cannot otherwise read.

## References

- https://wpsec.com/vuln/WPSEC-2026-0682/
- https://plugins.svn.wordpress.org/envira-gallery-lite/tags/1.16.2/
- https://wordpress.org/plugins/envira-gallery-lite/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0682/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
